public inbox for [email protected]
 help / color / mirror / Atom feed
This is experimental automated Linux kernel CVE triage research. Results are heuristic and may be incorrect. This site is not an official vendor advisory or severity source.
[CVE-2026-45948][LOW] ext4: fix memory leak in ext4_ext_shift_extents()
 2026-05-27 23:54 UTC 

[CVE-2026-45951][IMPORTANT] bpf: Fix a potential use-after-free of BTF object [ Upstream
 2026-05-27 23:46 UTC 

[CVE-2026-45953][LOW] md/raid5: fix IO hang with degraded array with llbitmap [ Upstream
 2026-05-27 23:40 UTC 

[CVE-2026-45955][LOW] md/md-llbitmap: fix percpu_ref not resurrected on suspend timeout [ Upstream
 2026-05-27 23:35 UTC 

[CVE-2026-45959][MODERATE 7.0] crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree [ Upstream
 2026-05-27 23:23 UTC 

[CVE-2026-45960][MODERATE REGULAR] hfsplus: return error when node already exists in hfs_bnode_create [ Upstream
 2026-05-27 23:20 UTC 

[CVE-2026-45961][LOW] gfs2: fix memory leaks in gfs2_fill_super error path [ Upstream
 2026-05-27 23:16 UTC 

[CVE-2026-45962][MODERATE 7.0] ublk: Validate SQE128 flag before accessing the cmd [ Upstream
 2026-05-27 23:13 UTC 

[CVE-2026-45963][LOW] ASoC: nau8821: Cancel delayed work on component remove [ Upstream
 2026-05-27 23:09 UTC 

[CVE-2026-45964][LOW] SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path
 2026-05-27 23:07 UTC 

[CVE-2026-45970][MODERATE 7.0] bonding: alb: fix UAF in rlb_arp_recv during bond up/down [ Upstream
 2026-05-27 22:53 UTC 

[CVE-2026-45971][LOW] bpf: Limit bpf program signature size [ Upstream
 2026-05-27 22:49 UTC 

[CVE-2026-45972][IMPORTANT] smb: client: fix potential UAF and double free in smb2_open_file() [ Upstream
 2026-05-27 22:43 UTC 

[CVE-2026-45975][IMPORTANT] ublk: use READ_ONCE() to read struct ublksrv_ctrl_cmd [ Upstream
 2026-05-27 22:34 UTC 

[CVE-2026-45982][LOW] ACPICA: Fix NULL pointer dereference in acpi_ev_address_space_dispatch() [ Upstream
 2026-05-27 22:20 UTC 

[CVE-2026-45983][MODERATE 7.0] nfsd: never defer requests during idmap lookup [ Upstream
 2026-05-27 22:16 UTC 

[CVE-2026-45984][IMPORTANT] gfs2: Fix use-after-free in iomap inline data write path [ Upstream
 2026-05-27 22:09 UTC 

[CVE-2026-45985][MODERATE 7.0] ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O [ Upstream
 2026-05-27 22:05 UTC 

[CVE-2026-45991][IMPORTANT] udf: fix partition descriptor append bookkeeping [ Upstream
 2026-05-27 21:49 UTC 

[CVE-2026-45992][LOW] ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path
 2026-05-27 21:47 UTC 

[CVE-2026-45994][MODERATE REGULAR] ibmasm: fix OOB reads in command_file_write due to missing size checks
 2026-05-27 21:41 UTC 

[CVE-2026-45996][MODERATE REGULAR] spi: imx: fix use-after-free on unbind
 2026-05-27 21:36 UTC 

[CVE-2026-45998][IMPORTANT] rxrpc: Fix potential UAF after skb_unshare() failure [ Upstream
 2026-05-27 21:29 UTC 

[CVE-2026-46000][MODERATE 7.0] rxrpc: Fix conn-level packet handling to unshare RESPONSE packets [ Upstream
 2026-05-27 21:24 UTC 

[CVE-2026-46002][LOW] ext2: reject inodes with zero i_nlink and valid mode in ext2_iget()
 2026-05-27 21:18 UTC 

[CVE-2026-43128][IMPORTANT] RDMA/umem: Fix double dma_buf_unpin in failure path [ Upstream
 2026-05-27 21:03 UTC 

[CVE-2026-46010][MODERATE REGULAR] rxrpc: Fix error handling in rxgk_extract_token()
 2026-05-27 21:01 UTC 

[CVE-2026-46014][LOW] KVM: SVM: Add missing save/restore handling of LBR MSRs
 2026-05-27 20:46 UTC 

[CVE-2026-46015][MODERATE 7.0] tcp: call sk_data_ready() after listener migration
 2026-05-27 20:42 UTC 

[CVE-2026-46017][MODERATE 7.0] mm: fix deferred split queue races during migration
 2026-05-27 20:36 UTC 

[CVE-2026-46022][MODERATE REGULAR] misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()
 2026-05-27 20:26 UTC 

[CVE-2026-46027][MODERATE REGULAR] net/smc: avoid early lgr access in smc_clc_wait_msg
 2026-05-27 20:15 UTC 

[CVE-2026-46033][IMPORTANT] crypto: authencesn - reject short ahash digests during instance creation
 2026-05-27 19:59 UTC 

[CVE-2026-46035][MODERATE 7.0] mm/page_alloc: return NULL early from alloc_frozen_pages_nolock() in NMI on UP
 2026-05-27 19:54 UTC 

[CVE-2026-46039][MODERATE 7.0] rxgk: Fix potential integer overflow in length check
 2026-05-27 19:45 UTC 

[CVE-2026-46042][LOW] mm/mempolicy: fix memory leaks in weighted_interleave_auto_store()
 2026-05-27 19:39 UTC 

[CVE-2026-46043][MODERATE 7.0] RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv
 2026-05-27 19:35 UTC 

[CVE-2026-46045][MODERATE 7.0] md/md-llbitmap: skip reading rdevs that are not in_sync
 2026-05-27 19:29 UTC 

[CVE-2026-46048][LOW] ALSA: caiaq: fix usb_dev refcount leak on probe failure
 2026-05-27 19:21 UTC 

[CVE-2026-46052][MODERATE 7.0] ceph: only d_add() negative dentries when they are unhashed [ Upstream
 2026-05-27 19:12 UTC 

[CVE-2026-46053][IMPORTANT] net: rds: fix MR cleanup on copy error
 2026-05-27 19:09 UTC 

[CVE-2026-46065][IMPORTANT] fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info [ Upstream
 2026-05-27 19:06 UTC 

[CVE-2026-46070][MODERATE REGULAR] md/raid5: validate payload size before accessing journal metadata
 2026-05-27 18:59 UTC 

[CVE-2026-46059][LOW] KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN
 2026-05-27 18:52 UTC 

[CVE-2026-46060][LOW] crypto: qat - fix IRQ cleanup on 6xxx probe failure
 2026-05-27 18:49 UTC 

[CVE-2026-46061][LOW] jbd2: fix deadlock in jbd2_journal_cancel_revoke()
 2026-05-27 18:45 UTC 

[CVE-2026-46084][MODERATE 7.0] RDMA/mana_ib: Disable RX steering on RSS QP destroy [ Upstream
 2026-05-27 17:22 UTC 

[CVE-2026-46093][MODERATE REGULAR] mm/vmalloc: take vmap_purge_lock in shrinker
 2026-05-27 17:00 UTC 

[CVE-2026-46095][MODERATE REGULAR] md/md-llbitmap: raise barrier before state machine transition
 2026-05-27 16:54 UTC 

[CVE-2026-46023][MODERATE 7.0] dm mirror: fix integer overflow in create_dirty_log()
 2026-05-27 16:44 UTC 

[CVE-2026-46032][MODERATE 7.0] KVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT
 2026-05-27 16:35 UTC 

[CVE-2026-46012][MODERATE 7.0] rxrpc: Fix memory leaks in rxkad_verify_response()
 2026-05-27 16:32 UTC 

[CVE-2026-46102][MODERATE 7.0] net: strparser: fix skb_head leak in strp_abort_strp()
 2026-05-27 16:26 UTC 

[CVE-2026-45988][MODERATE 7.0] rxrpc: Fix re-decryption of RESPONSE packets
 2026-05-27 16:23 UTC 

[CVE-2026-46021][MODERATE 7.0] thermal: core: Fix thermal zone governor cleanup issues [ Upstream
 2026-05-27 16:20 UTC 

[CVE-2026-46038][LOW] net: qrtr: ns: Free the node during ctrl_cmd_bye()
 2026-05-27 16:15 UTC 

[CVE-2026-46071][LOW] KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12
 2026-05-27 16:12 UTC 

[CVE-2026-46003][LOW] net: qrtr: ns: Limit the total number of nodes [ Upstream
 2026-05-27 16:10 UTC 

[CVE-2026-45997][LOW] scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails
 2026-05-27 16:03 UTC 

[CVE-2026-46047][MODERATE 7.0] net: qrtr: ns: Fix use-after-free in driver remove()
 2026-05-27 16:00 UTC 

[CVE-2026-46103][LOW] can: ucan: fix devres lifetime
 2026-05-27 15:57 UTC 

[CVE-2026-45987][LOW] KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2
 2026-05-27 15:54 UTC 

[CVE-2026-46076][MODERATE 7.0] KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1
 2026-05-27 15:47 UTC 

[CVE-2026-46063][LOW] x86/shstk: Prevent deadlock during shstk sigreturn [ Upstream
 2026-05-27 15:44 UTC 

[CVE-2026-46079][MODERATE REGULAR] rbd: fix null-ptr-deref when device_add_disk() fails
 2026-05-27 15:39 UTC 

[CVE-2026-46050][MODERATE REGULAR] md/raid10: fix deadlock with check operation and nowait requests
 2026-05-27 15:35 UTC 

[CVE-2026-45999][MODERATE REGULAR] erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() [ Upstream
 2026-05-27 15:29 UTC 

[CVE-2026-46069][MODERATE 7.0] wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() [ Upstream
 2026-05-27 15:25 UTC 

[CVE-2026-46054][IMPORTANT] selinux: fix overlayfs mmap() and mprotect() access checks
 2026-05-27 15:22 UTC 

[CVE-2026-46066][MODERATE REGULAR] ceph: fix num_ops off-by-one when crypto allocation fails
 2026-05-27 15:16 UTC 

[CVE-2026-46101][LOW] netfilter: reject zero shift in nft_bitwise
 2026-05-27 15:14 UTC 

[CVE-2026-46089][LOW] zram: do not forget to endio for partial discard requests
 2026-05-27 15:10 UTC 

[CVE-2026-46083][LOW] spi: fix resource leaks on device setup failure [ Upstream
 2026-05-27 15:07 UTC 

[CVE-2026-46049][LOW] ALSA: ctxfi: Add fallback to default RSR for S/PDIF
 2026-05-27 15:03 UTC 

[CVE-2026-46051][MODERATE REGULAR] md/raid5: fix soft lockup in retry_aligned_read()
 2026-05-27 15:00 UTC 

[CVE-2026-46056][IMPORTANT] Bluetooth: hci_event: fix potential UAF in SSP passkey handlers
 2026-05-27 14:57 UTC 

[CVE-2026-46026][LOW] net: qrtr: ns: Limit the maximum number of lookups [ Upstream
 2026-05-27 14:53 UTC 

[CVE-2026-46046][LOW] ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()
 2026-05-27 14:48 UTC 

[CVE-2026-46024][MODERATE REGULAR] libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply()
 2026-05-27 14:45 UTC 

[CVE-2026-46028][MODERATE 7.0] crypto: algif_aead - snapshot IV for async AEAD requests
 2026-05-27 14:43 UTC 

[CVE-2026-46018][LOW] ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES
 2026-05-27 14:39 UTC 

[CVE-2026-46099][IMPORTANT] net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels
 2026-05-27 14:29 UTC 

[CVE-2026-46088][LOW] ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names()
 2026-05-27 14:26 UTC 

[CVE-2026-46004][MODERATE 7.0] ALSA: caiaq: Handle probe errors properly
 2026-05-27 14:22 UTC 

[CVE-2026-46040][LOW] inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails
 2026-05-27 14:19 UTC 

[CVE-2026-46068][LOW] crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx [ Upstream
 2026-05-27 14:15 UTC 

[CVE-2026-46005][LOW] xfs: fix a resource leak in xfs_alloc_buftarg() [ Upstream
 2026-05-27 14:11 UTC 

[CVE-2026-46078][MODERATE REGULAR] erofs: fix the out-of-bounds nameoff handling for trailing dirents
 2026-05-27 14:07 UTC 

[CVE-2026-46037][MODERATE 7.0] ipv4: icmp: validate reply type before using icmp_pointers
 2026-05-27 14:03 UTC 

[CVE-2026-46092][LOW] wifi: rtw88: check for PCI upstream bridge existence pci_upstream_bridge() returns NULL if the device is on a root bus. If 8821CE is installed in the system with such a PCI topology, the probing routine will crash. This has probably been unnoticed as 8821CE is mostly supplied in laptops where there is a PCI-to-PCI bridge located upstream from the device. However the card might be installed on a system with different configuration. Check if the bridge does exist for the specific workaround to be applied. Found by Linux Verification Center (linuxtesting.org) with Svace static analysis tool. Fixes: 24f5e38 ("rtw88: Disable PCIe ASPM while doing NAPI poll on 8821CE") Cc: [email protected] Signed-off-by: Fedor Pchelkin <[email protected]> Acked-by: Ping-Ke Shih <[email protected]> Signed-off-by: Ping-Ke Shih <[email protected]> Link: https://patch.msgid.link/[email protected]
 2026-05-27 13:56 UTC 

[CVE-2026-46094][MODERATE REGULAR] ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access
 2026-05-27 13:54 UTC 

[CVE-2026-45912][MODERATE 7.0] ext4: don't cache extent during splitting extent
 2026-05-27 13:40 UTC 

[CVE-2026-45891][MODERATE 7.0] net: hns3: fix double free issue for tx spare buffer [ Upstream
 2026-05-27 13:37 UTC 

[CVE-2026-45968][LOW] cpuidle: Skip governor when only one idle state is available [ Upstream
 2026-05-27 13:33 UTC 

[CVE-2026-45944][MODERATE 7.0] iommu/vt-d: Clear Present bit before tearing down context entry [ Upstream
 2026-05-27 13:27 UTC 

[CVE-2026-45910][MODERATE 7.0] RDMA/rxe: Fix race condition in QP timer handlers [ Upstream
 2026-05-27 13:24 UTC 

[CVE-2026-45868][LOW] pinctrl: single: fix refcount leak in pcs_add_gpio_func() [ Upstream
 2026-05-27 13:19 UTC 

[CVE-2026-45973][MODERATE REGULAR] RDMA/mlx5: Fix UMR hang in LAG error state unload [ Upstream
 2026-05-27 13:15 UTC 

[CVE-2026-45855][MODERATE REGULAR] ata: libata-scsi: avoid Non-NCQ command starvation [ Upstream
 2026-05-27 13:12 UTC 

[CVE-2026-45857][MODERATE REGULAR] scsi: csiostor: Fix dereference of null pointer rn [ Upstream
 2026-05-27 13:09 UTC 

[CVE-2026-45949][MODERATE REGULAR] hwrng: core - use RCU and work_struct to fix race condition [ Upstream
 2026-05-27 13:05 UTC 

[CVE-2026-45974][MODERATE REGULAR] btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found [ Upstream
 2026-05-27 13:02 UTC 

[CVE-2026-45981][MODERATE REGULAR] s390/cio: Fix device lifecycle handling in css_alloc_subchannel() [ Upstream
 2026-05-27 12:58 UTC 

[CVE-2026-45873][LOW] netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets [ Upstream
 2026-05-27 12:51 UTC 

[CVE-2026-45840][MODERATE 7.0] openvswitch: cap upcall PID array size and pre-size vport replies [ Upstream
 2026-05-27 12:30 UTC 

[CVE-2026-45845][MODERATE REGULAR] net/sched: taprio: fix NULL pointer dereference in class dump [ Upstream
 2026-05-27 12:22 UTC 

[CVE-2026-45846][MODERATE REGULAR] bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() [ Upstream
 2026-05-27 10:15 UTC 

[CVE-2026-45842][MODERATE REGULAR] slip: reject VJ receive packets on instances with no rstate array [ Upstream
 2026-05-27 10:12 UTC 

[CVE-2026-45838][MODERATE REGULAR] bpf: fix end-of-list detection in cgroup_storage_get_next_key() [ Upstream
 2026-05-27 10:09 UTC 

[CVE-2026-45843][MODERATE REGULAR] slip: bound decode() reads against the compressed packet length [ Upstream
 2026-05-27 10:05 UTC 

[CVE-2026-45837][IMPORTANT] bpf: Fix use-after-free in arena_vm_close on fork
 2026-05-27 10:02 UTC 

[CVE-2026-45844][MODERATE REGULAR] netfilter: arp_tables: fix IEEE1394 ARP payload parsing [ Upstream
 2026-05-27  9:55 UTC 

[CVE-2026-45841][MODERATE REGULAR] netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO [ Upstream
 2026-05-27  9:51 UTC 

[CVE-2026-45836][MODERATE 7.0] Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_get_sndtimeo_cb()
 2026-05-26 16:59 UTC 

[CVE-2026-45834][MODERATE 7.0] Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb()
 2026-05-26 16:55 UTC 

[CVE-2026-45835][MODERATE 7.0] Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb()
 2026-05-26 16:52 UTC 

[CVE-2026-46300][IMPORTANT] net: skbuff: propagate shared-frag marker through frag-transfer helpers
 2026-05-23 12:52 UTC 

[CVE-2026-31402][IMPORTANT] nfsd: fix heap overflow in NFSv4.0 LOCK replay cache [ Upstream
 2026-05-21 20:57 UTC 

[CVE-2025-68741][IMPORTANT] scsi: qla2xxx: Fix improper freeing of purex item [ Upstream
 2026-05-21 20:44 UTC 

[CVE-2026-31772][IMPORTANT] Bluetooth: hci_sync: fix stack buffer overflow in hci_le_big_create_sync
 2026-05-21 20:33 UTC 

[CVE-2026-31787][MODERATE 7.0] xen/privcmd: fix double free via VMA splitting
 2026-05-21 20:23 UTC 

[CVE-2026-43502][MODERATE REGULAR] net/rds: handle zerocopy send cleanup before the message is queued
 2026-05-21 15:09 UTC 

[CVE-2026-43494][IMPORTANT] net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages are released with put_page(), and rm->data.op_mmp_znotifier is cleared. But we fail to properly clear rm->data.op_nents. Later when rds_message_purge() is called from rds_sendmsg() the cleanup loop iterates over the incorrectly non zero number of op_nents and frees them again. Fix this by properly resetting op_nents when it should be in rds_message_zcopy_from_user(). Fixes: 0cebacc ("rds: zerocopy Tx support.") Signed-off-by: Allison Henderson <[email protected]> Reviewed-by: Simon Horman <[email protected]> Link: https://patch.msgid.link/[email protected] Signed-off-by: Jakub Kicinski <[email protected]>
 2026-05-21 14:52 UTC 

[CVE-2026-43496][LOW] net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked
 2026-05-21 12:57 UTC 

[CVE-2026-43501][IMPORTANT] ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
 2026-05-21 12:52 UTC 

[CVE-2026-43330][MODERATE REGULAR] crypto: caam - fix overflow on long hmac keys [ Upstream
 2026-05-21 11:25 UTC 

[CVE-2026-43023][IMPORTANT] Bluetooth: SCO: fix race conditions in sco_sock_connect() [ Upstream
 2026-05-21  4:38 UTC 

[CVE-2026-43037][IMPORTANT] ip6_tunnel: clear skb2->cb[] in ip4ip6_err() [ Upstream
 2026-05-21  4:28 UTC 

[CVE-2024-39503][MODERATE 7.0] netfilter: ipset: Fix race between namespace cleanup and gc in the list:set type [ Upstream
 2026-05-21  3:35 UTC 

[CVE-2026-43038][IMPORTANT] ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() [ Upstream
 2026-05-21  2:42 UTC 

[CVE-2022-50835][LOW] jbd2: add miss release buffer head in fc_do_one_pass()
 2026-05-21  2:38 UTC 

[CVE-2026-31431][IMPORTANT] crypto: algif_aead - Revert to operating out-of-place [ Upstream
 2026-05-21  2:22 UTC 

[CVE-2026-43500][IMPORTANT] rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
 2026-05-21  1:43 UTC 

[CVE-2026-43304][IMPORTANT] libceph: define and enforce CEPH_MAX_KEY_LEN [ Upstream
 2026-05-20 23:59 UTC 

[CVE-2026-43208][MODERATE 7.0] net: do not pass flow_id to set_rps_cpu() [ Upstream
 2026-05-20 21:36 UTC 

page:              |  | latest

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox